OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-61628

HIGH · CVSS 8.1 EPSS 0.43% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Nginx Ignition versions prior to 2.41.1 are vulnerable to a flaw that allows remote unauthenticated attackers to create administrator accounts by exploiting a race condition in the onboarding process. This vulnerability can lead to unauthorized access with full ReadWrite permissions, posing a significant risk to the integrity and security of the web server. Organizations using affected versions should prioritize upgrading to 2.41.1 or later to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61628
Severity
HIGH
CVSS
8.1
EPSS
0.43%
Nginx

Original NVD Description

nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions. Because the handler uses a check-then-act (TOCTOU) pattern between the "onboarding already completed?" check and the user-creation write, with no atomic guard, a remote unauthenticated attacker who can reach an instance in its pre-onboarding state can create an administrator account for themselves — and concurrent requests can create multiple admin accounts in a single race. Version 2.41.1 patches the issue.